Strategy · Partner environment & model risk
Make governed card data a product every team can trust.
The north star: a new co-brand partner reaches analytics go-live in weeks, not quarters - with row-, column-, and purpose-level entitlements enforced by construction, and ML that carries its own governance. Atlas is how a Card D&A team onboards Partner Aurora as a first-class data-product domain without ever loosening the controls.
Treat data as a product: owned, contracted, discoverable, SLA-governed - not a pile of tables behind a ticket queue.
Entitlements are the platform, not a feature. Row scope, purpose, masking, and audit are designed in from day one.
A partner reaches go-live in weeks because the controls are reusable, not rebuilt per engagement.
Every model is accountable to a monitored business metric and an SR 11-7 lifecycle, or it doesn't ship.
Build vs buy - where this pattern honestly sits
The mechanism here - row policies + column masking + purpose tags + audit - is deliberately commodity: Immuta, Databricks Unity Catalog, and Snowflake Horizon all ship versions of it. The defensible part for an issuer is not the mechanism; it's the co-brand semantics packaged on top. Positioning is qualitative and illustrative - no vendor pricing is quoted because none was independently verified.
Policy orchestration across engines (Snowflake, Databricks, warehouse mix). Strongest when the estate is multi-engine and policy count is large. You still have to model co-brand partners, purposes, and audit semantics yourself - the platform gives you enforcement primitives, not your data-sharing agreement.
Row filters and masking native to the lakehouse/warehouse - no extra vendor, rides the existing engine bill. The natural default for a single-engine estate. Same gap: partner row-scope and purpose-as-access-dimension are YOUR semantics to define and test.
The layer an issuer builds EITHER way: co-brand partner scope as a first-class row dimension, purpose as a queryable access dimension, masking tied to role capability, audit-by-default - expressed in ~250 lines of committed SQL (src/lib/atlas/sql/0002-0003). The recommendation it encodes: buy the generic policy plane, build the co-brand semantics, and keep them small enough to review.
The unit that matters: marginal cost of co-brand partner N+1
structural argument · no measured dollarsAn issuer with a large co-brand book onboards partners repeatedly. The fundable case for a governed plane is not year-one ROI - it's that partner onboarding flips from a per-partner build to a per-partner configuration, while the reviewable control surface stays constant instead of growing with every extract.
| Cost driver, per new partner | Bespoke extract environment | Governed-domain pattern (this artifact) |
|---|---|---|
| Data plumbing | New pipelines + a partner-shaped copy of the data | Zero new copies - share in place; one partner_scope value on existing products |
| Row / column controls | Re-implemented and re-reviewed per extract | One entitlement_roles row; the same committed policies (0002) apply unchanged |
| Security & audit review | A NEW surface to review; extracts keep leaking after handoff | The reviewed surface is constant (~250 lines of SQL in this repo); audit-by-default |
| Ongoing liability | Every extract is standing PII exposure with its own lifecycle | Revoke = delete one role row; nothing partner-shaped persists to clean up |
Deliberately no invented dollar figures: engineering-cost and vendor-price claims here would be unverifiable. The demonstrable claim is the shape of the cost curve - in this repo, “onboard Partner Aurora” is literally one role row (0004) plus one scope value (0005), against an unchanged, committed policy set (0002-0003).
Roadmap
Now / Next / Later - the partner-onboarding path, with explicit sequencing.
this quarter - partner go-live path
Land Nova authorizations into the bronze lake; conform to silver. Stand up partner row-scope entitlements.
Real RLS row-scope + purpose-based access + PII masking + full audit on Tier-1 products.
Row-filtered Nova reporting mart with freshness/availability SLAs for partner delivery.
1-2 quarters - productize & automate
Curated, contracted, lineage-tracked flagship product for analysts + DS.
Promote fraud-detection-xgb with monitoring + drift triggers + adverse-action reason codes.
Natural-language querying that respects entitlements; SELECT-only, audited.
self-serve & governed gen-AI
Governed metrics layer so every team computes the same KPI the same way.
RAG over the data dictionary; automated executive readouts from KPI state.
Purpose + residency entitlements for the Bengaluru team accessing US card data.